OPEN BETA
NEWS YADS is now open source β€” the full source code is available on GitHub. Read more β†’
OPEN BETA
v4.5.28 STABLE | NOW OPEN SOURCE

Master Your
Attack Surface

The all-in-one, open-source reconnaissance platform. Visualize threats, track assets, and secure your infrastructure with cutting-edge precision β€” free for anyone to use, run, and improve.

YADS Professional Dashboard

Security Through Transparency

YADS provides deep insights into your digital presence, identifying vulnerabilities before they can be exploited.

πŸ”

Asset Discovery

Automatic detection of shadow IT, subdomains, and unknown cloud resources across all major providers.

πŸ•ΈοΈ

Attack Paths

Visualize attacker movements from open ports to sensitive data using interactive D3.js graphs.

πŸ”

PQC Readiness

Prepare for the quantum era with automated CBOM generation and analysis of your cryptographic assets.

πŸ“œ

Hash-Chain Audit Logs

DORA-compliant tamper-proof audit trails using cryptographic chaining of every system action.

⏱️

SLA Management

Automated remediation tracking with BSI-compliant deadlines for Critical, High, and Medium findings.

πŸ—οΈ

Encrypted BYOK

All sensitive integration keys are protected at rest with AES-256 (Bring Your Own Key security).

Platform Highlights

NEW in v4.0

AI & Automation

AI Intelligence Assistant, AI-generated Finding Descriptions, and the AI Add-on Lab β€” grounded in your scan data, always with a human in the loop.

  • πŸ€– Conversational AI grounded in your findings
  • πŸ“ Auto-generate finding descriptions with fix steps
  • πŸ§ͺ Generate custom scanner modules from plain language
  • βœ‹ No autonomous deployment β€” human review always required
Learn more β†’
AI Intelligence Assistant
NEW
Attack Path Visualization

Visual Attack Paths

Identify complex vulnerability chains in real-time with granular analysis.

NEW
Cloud Asset Monitoring

Cloud Asset Monitoring

Seamless integration for GCP, Azure, and AWS cloud infrastructures.

v4.0
WAF Log Analysis

WAF Analysis Suite

Deep dive into Web Application Firewall logs for advanced bot detection.

BETA
Data Leak Monitoring

Data Leak Monitor

Monitor darknet and paste sites for compromised credentials and data leaks.

Included

Active Validation

Don't just find vulnerabilities β€” confirm they're still real. Purpose-built validators re-check individual findings on demand and return a verdict in seconds.

  • βœ… Not confirmed β€” finding likely resolved
  • πŸ”΄ Confirmed β€” still exploitable right now
  • πŸ” 7 built-in validators, zero configuration
  • πŸ“‹ Evidence persisted for audit & compliance (NIS2, DORA, ISO 27001)
Learn more β†’
Active Validation β€” Finding Detail with Validate Now button
NEW
Vibe Sessions Asset Discovery

AI-Scored Discovery

Interactive "Vibe Sessions" for asset discovery with AI relevance scoring and signal analysis.

COMPLIANCE
Historical Compliance Trends

Framework Trends

Track historical compliance progress against SOC2, GDPR, and NIS2 frameworks automatically.

UNIQUE
Static TOGO Report Export

TOGO Offline Hub

Export interactive, self-contained HTML/PDF reports for secure offline offline viewing or client delivery.

PLATFORM
Worker Node Telemetrie

Worker Orchestration

Global worker node telemetry, load balancing, and multi-region scan orchestration for large-scale ops.

SECURITY
Ed25519 Modul-Verifizierung

Module Signing

Cryptographic integrity verification for every add-on module via Ed25519 signatures.

NEW in v4.0
Intelligence Hub β€” JARM + Canary Tokens

Intelligence Hub

JARM TLS fingerprinting, Origin-IP WAF bypass detection, and Canary Token deployment β€” in one unified view.

πŸ”±
v4.0 β€” Flagship Feature

Zenith Risk Orchestrator

The first tenant-wide attack path intelligence engine for YADS. Zenith calculates in real time the actual threat posture of your entire perimeter β€” not target by target, but as a connected attack network.

  • ⚑Attackability Score (0–100) β€” 5 factors: port exposure, finding severity, tech debt, reachability
  • πŸ›£οΈDijkstra Attack Paths with MITRE ATT&CK mapping, lethality score and time-to-breach estimate
  • πŸ’ŽCrown Jewel Registry β€” automatic detection and manual prioritization of critical assets
  • πŸ“ŠRemediation ROI β€” which measure reduces attack surface the most? With What-If simulation
  • πŸ€–AI Narrative on Demand β€” LLM-generated threat analysis for each path, at the click of a button
Zenith Risk Orchestrator Dashboard
Up to 10 Attack Paths
Real-Time Progress
MITRE ATT&CK
πŸ‘₯
v4.5 β€” Flagship Feature Β· Phase 6

ShadowTwin

The first AI adversary simulation engine for YADS. ShadowTwin runs 90,000 Monte Carlo attack campaigns against a digital replica of your environment β€” and shows you exactly where you would lose, before an attacker finds out.

  • 🎯3Γ—3 Attack Heatmap β€” win probability per persona (Script Kiddie, APT, Ransomware) Γ— win condition
  • πŸ“‘EPSS + CISA KEV β€” exploit selection weighted by real-world exploit probability, not theoretical CVSS
  • πŸ›‘οΈIntervention Impact Analysis β€” change WAF/IDS/IPS, see the delta in win probabilities instantly
  • πŸ“„Dual PDF Reports β€” Technical + Management report on demand, EN + DE
  • πŸ€–AI Threat Narrative β€” Gemini generates realistic attack story for each persona, on demand
ShadowTwin War Room
90k Simulations
3 Personas
EPSS + CISA KEV

What's New

Highlights since v4.5.8 β€” full changelog β†’

πŸ”’

Backup & Restore Overhaul

Instance UUIDs are never overwritten during restore. Version compatibility check before import. Real-time progress bar.

πŸ€–

AI Analysis & LLM Defaults

Default LLM provider selections for faster AI setup. Improved AI cleanup logic with hard-rule filtering for more reliable finding prioritization.

πŸ“₯

Import Findings Category

Findings imported from Nessus, Burp, OpenVAS, Qualys, ZAP and Nuclei now carry the imported category β€” filterable and included in PDF exports.

βš™οΈ

Settings & About Page

New About tab in Settings shows running version, edition, instance UUID and license info at a glance. Restore options now use granular keep/purge flags.

πŸ”—

Contacts & Activations Pagination

Support portal contact and activation lists now paginate at 50 rows β€” eliminates memory pressure on large deployments.

πŸ› οΈ

Stability & Bug Fixes

Scanner module compatibility fixes, RabbitMQ consumer timeout raised to 70 min, sequence reset after restore, CSRF handling improvements.

Free & Open Source

YADS is fully open source β€” every feature, no license keys, no tiers. Grab the code, run it yourself, and help shape where it goes next.

Get Started Read the Docs

YADS Security was born from a vision for maximum visibility. It's not just a tool, but a living security ecosystem built for tomorrow's challenges.